Skip to main content

Workflow Template: Poll Microsoft Outlook on a Schedule for New Messages for Cases

Automatically pull new messages from Outlook on a schedule, extract its components, enrich observables and create cases with a field mapper.

Updated yesterday

The "Poll Microsoft Outlook on a Schedule for New Messages for Cases" workflow template is designed to streamline email case management by automatically retrieving new messages from Outlook at regular intervals. It extracts and enriches email components, such as EML files, and generates detailed Torq cases. This process includes URL defanging, QR code scanning in attachments, and SPF/DKIM verification, ensuring comprehensive email analysis and documentation. Ideal for businesses seeking efficient email threat management and case creation.

Use Cases

Case Management

Workflow Breakdown

  1. Polls Outlook for new messages, passing EML files to a nested workflow for content gathering.

  2. Enrichment/linking occurs before mapping to generate a Torq case with email/nested email info.

  3. EML inspection resolves URL hostnames, provides verdicts, and defangs URLs for the Torq case.

  4. Image attachments are checked for QR codes; findings and observables are added as case comments.

  5. Torq case includes EML details, HTML header notes, SPF/DKIM verdicts, and an HTML body screenshot.

Vendors

Scripting, Utils, Microsoft Outlook, Microsoft 365, Torq, Torq Cases, Data Transformation

Tips

Did this answer your question?